TL;DR verdict
Ethena is conditionally safe. No smart contract hacks have been recorded against the protocol, and its code has been reviewed by three reputable audit firms: Pashov, Quantstamp, and Spearbit. However, USDe’s delta-neutral strategy depends on centralized exchanges to hold derivative positions, introducing significant counterparty and custody risks. With a TVL of roughly $4.5B and a relatively short operational history since a 2024 launch, Ethena remains higher-risk than fully decentralized stablecoin alternatives. Notably, on 11 October 2025 USDe briefly traded down to about $0.65 on Binance during a market-wide crash — a venue-specific dislocation caused by Binance's margin-collateral pricing, not an Ethena smart-contract failure; USDe held near parity elsewhere and remained fully backed. Use with caution and only after understanding the centralization vectors.
- Audits: Pashov, Quantstamp, Spearbit
- Incidents: None recorded in DeFi Intel's database as of 2026-05-28
- Centralization risk: USDe relies on CEX custody for its hedging positions
Audit history
Ethena’s smart contracts have been audited by three security firms:
- Pashov — conducted a review of the core USDe and staking contracts. No critical vulnerabilities were publicly disclosed post-audit.
- Quantstamp — performed a comprehensive audit of the Ethena protocol, focusing on economic attacks and edge cases in the minting/redeeming logic.
- Spearbit — reviewed the off-chain components and oracle integrations, with a focus on the interaction between the on-chain vaults and CEX execution layers.
All audits were completed before mainnet launch, and the protocol has not experienced any post-audit incidents. However, the rapid expansion to new chains (Ethereum, Solana, Arbitrum, Base, Bybit, Mantle) may introduce new attack surfaces that have not yet been audited on every deployment.
Incidents and exploits
Ethena has not suffered an on-chain smart-contract exploit as of 2026-07-15, despite holding roughly $4.5B in value, and there has been no loss of funds due to oracle manipulation or a governance attack. It has, however, weathered several stress events. In September 2024 Ethena Labs' domain registrar account was briefly compromised (a front-end/DNS incident that did not touch protocol funds). In February 2025 the Bybit hack — a key CEX venue for USDe hedging — sparked depeg fears, but Ethena confirmed backing assets were held off-exchange with a custodian. And on 11 October 2025, USDe momentarily depegged to ~$0.65 on Binance during a broad crypto crash; the drop was isolated to Binance and tied to how its unified-margin system priced collateral, not to under-collateralization of USDe, which stayed near $1 elsewhere. These episodes validated the design under duress but underline USDe's exposure to centralized-venue and market-structure risk.
Smart contract risks
Ethena’s contracts are relatively new (launched 2024), so they lack the multi-year battle testing of protocols like Aave or Lido. The protocol uses a proxy-based upgrade pattern, which allows the team to modify logic but requires trust in the multisig signers and the governance process. Oracle dependencies exist for pricing the USDe peg and the underlying hedging assets; any manipulation or failure in these oracles could lead to incorrect minting or liquidations. Additionally, the integration with multiple chains increases the complexity and potential for cross-chain vulnerabilities.
Operational and counterparty risks
The primary risk for Ethena is counterparty exposure. USDe’s stability is maintained by shorting perpetual futures on centralized exchanges, meaning a significant portion of the protocol’s collateral resides on CEXs like Bybit. Exchange hacks, insolvencies, or withdrawal halts could directly impact USDe’s backing and cause a depeg. Team transparency is moderate; Ethena Labs operates the protocol, but the governance token ENA is used for DAO decisions, though key decision-making remains concentrated. Regulatory risk is elevated—stablecoin issuers face uncertain legal frameworks, especially those involving centralized intermediaries. There is no known insurance fund or Nexus Mutual-style coverage for USDe holders, so losses from a counterparty failure would likely be socialized among users.
How to use it more safely
- Limit USDe exposure to an amount you can afford to lose; treat it as a higher-risk yield product.
- Regularly monitor the health of the CEXs used by Ethena, particularly Bybit, for insolvency rumors or withdrawal issues.
- Use a hardware wallet for holding sUSDe and avoid keeping large amounts on a single chain.
- Diversify stablecoin holdings; do not keep all stablecoins in USDe.
- Stay informed about Ethena DAO governance votes and multisig changes that could affect protocol security.
- Consider using only the Ethereum mainnet deployment, where audits are most comprehensive, until newer chain deployments mature.
Verdict
Ethena sits at a 7.2 out of 10 on DeFi Intel’s safety scale. It has passed multiple audits and has no exploit history, but its reliance on centralized exchange infrastructure introduces unique risks not present in overcollateralized decentralized stablecoins. If you can tolerate the counterparty and regulatory uncertainties, USDe may offer attractive yields, but it should be approached as a conditional safe asset rather than a fully trust-minimized one.
DeFi Intel publishes editorial research, not financial advice. Smart contract risk is never zero. Do your own research and consider position sizing accordingly.